StackRadar

CVE-2026-49265

Medium

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
—
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
524
of 17,957 indexed, latest versions
Container images
471
deployed by those charts
Fix available
1 of 1
affected package

Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)

Carried by container images the latest versions of 524 of 17,957 indexed charts deploy, on 471 images.

Affected packageAffected versionsFixed inImages
oauthlibpypi3.0.1, 3.0.2, 3.1.0, 3.1.1+4 more4.0.0471
OSV records
GHSA-xpv3-w29h-x7cv
Trending
Rank 25 in indexed charts, since 30 Sept 2026. See the ranking →

Charts affected

524 by stars
ChartLatestAffected imagesRadar Score
geomapfishgeomapfish0.8.01 of 3See more

geomapfish geomapfish 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
camptocamp/geomapfishapp-geoportal:latestae874f70cc16
oauthlib@3.2.2
4.0.0

Open the chart page →

6,992
volume-autoscalergke-volume-autoscaler3.0.21 of 1See more

volume-autoscaler gke-volume-autoscaler 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
shadowrhyder/gke-volume-autoscaler:3.0.24aae9270356a
oauthlib@3.3.1
4.0.0

Open the chart page →

926
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
oauthlib@3.1.1
4.0.0

Open the chart page →

3,174
docker-registry-gcgmelilloVerified publisher0.1.91 of 1See more

docker-registry-gc gmelillo 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
gmelillo/registry:0.1.8c599d608a2f7
oauthlib@3.3.1
4.0.0

Open the chart page →

1,006
gnp-stackgnp-stack0.0.51 of 14See more

gnp-stack gnp-stack 0.0.5

1 of the 14 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
oauthlib@3.3.1
4.0.0

Open the chart page →

13,674
platformgoofy-chart0.1.01 of 1See more

platform goofy-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
devopsgoofy/k8s-platform:latestad865312099f
oauthlib@3.2.2
4.0.0

Open the chart page →

3,003
kube-prometheus-stackgpg-dev84.0.01 of 6See more

kube-prometheus-stack gpg-dev 84.0.0

1 of the 6 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
oauthlib@3.3.1
4.0.0

Open the chart page →

4,432
grafana-dashboard-convertergrafana-dashboard-converterVerified publisher0.3.101 of 1See more

grafana-dashboard-converter grafana-dashboard-converter 0.3.10

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kenchrcum/grafana-dashboard-converter:0.3.105310497aea3f
oauthlib@3.3.1
4.0.0

Open the chart page →

983
helixhelix1.4.31 of 2See more

helix helix 1.4.3

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
oauthlib@3.3.1
4.0.0

Open the chart page →

6,131
home-assistanthelm-chart-roeiVerified publisher2025.3.01 of 1See more

home-assistant helm-chart-roei 2025.3.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2025.3.026c51e44d932
oauthlib@3.2.2
4.0.0

Open the chart page →

5,113
mlflowhelm-charts-nr1.0.101 of 1See more

mlflow helm-charts-nr 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
larribas/mlflow:1.9.105ccb0b46bfb
oauthlib@3.1.0
4.0.0

Open the chart page →

4,535
newrelic-controllerhelm-charts-nr1.2.01 of 1See more

newrelic-controller helm-charts-nr 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
maxrocketinternet/newrelic-controller:0.8ff66958597f0
oauthlib@3.1.0
4.0.0

Open the chart page →

919
postgres-controllerhelm-charts-nr1.4.01 of 1See more

postgres-controller helm-charts-nr 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
maxrocketinternet/postgres-controller:0.572ac4d33b99d
oauthlib@3.1.0
4.0.0

Open the chart page →

946
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
oauthlib@3.1.0
4.0.0

Open the chart page →

8,477
chiefonboardinghelmforgeVerified publisher1.1.151 of 3See more

chiefonboarding helmforge 1.1.15

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
oauthlib@3.3.1
4.0.0

Open the chart page →

8,083
hermes-agenthelmforgeVerified publisher1.0.11 of 1See more

hermes-agent helmforge 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.9.24fca358f12efd
oauthlib@3.3.1
4.0.0

Open the chart page →

6,076
jupyterhubhelmforgeVerified publisher1.0.61 of 3See more

jupyterhub helmforge 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
oauthlib@3.3.1
4.0.0

Open the chart page →

5,903
langflowhelmforgeVerified publisher2.0.21 of 1See more

langflow helmforge 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
langflowai/langflow:1.12.334055a07d446
oauthlib@3.3.1
4.0.0

Open the chart page →

244
medikeephelmforgeVerified publisher2.0.21 of 3See more

medikeep helmforge 2.0.2

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/afairgiant/medikeep:v0.71.0086579173033
oauthlib@3.3.1
4.0.0

Open the chart page →

5,407
netboxhelmforgeVerified publisher2.0.21 of 4See more

netbox helmforge 2.0.2

1 of the 4 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
oauthlib@3.3.1
4.0.0

Open the chart page →

4,094
olivetinhelmforgeVerified publisher1.2.21 of 2See more

olivetin helmforge 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jamesread/olivetin:3000.20.0f3066e207efd
oauthlib@3.3.1
4.0.0

Open the chart page →

298
hetzner-s3-operatorhetzner-s3-operatorVerified publisher0.1.31 of 1See more

hetzner-s3-operator hetzner-s3-operator 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
oauthlib@3.3.1
4.0.0

Open the chart page →

689
changedetectionhomeenterpriseinc0.2.01 of 2See more

changedetection homeenterpriseinc 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.44534b9bc5c46e
oauthlib@3.2.2
4.0.0

Open the chart page →

1,974
homeassistanthomeenterpriseinc0.3.01 of 1See more

homeassistant homeenterpriseinc 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2022.3.5565751f33794
oauthlib@3.2.0
4.0.0

Open the chart page →

7,947
paperlesshpVerified publisher0.1.21 of 5See more

paperless hp 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
oauthlib@3.3.1
4.0.0

Open the chart page →

29,775
browserlessicoretechVerified publisher0.16.61 of 1See more

browserless icoretech 0.16.6

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
oauthlib@3.2.2
4.0.0

Open the chart page →

2,479
monitoring-stackict-platformVerified publisher0.4.01 of 13See more

monitoring-stack ict-platform 0.4.0

1 of the 13 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
oauthlib@3.3.1
4.0.0

Open the chart page →

9,937
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
oauthlib@3.1.1
4.0.0

Open the chart page →

117,870
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
oauthlib@3.3.1
4.0.0

Open the chart page →

2,502
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
oauthlib@3.1.1
4.0.0

Open the chart page →

7,041
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
oauthlib@3.2.2
4.0.0

Open the chart page →

2,653
pgadmininseefrlab3.2.01 of 1See more

pgadmin inseefrlab 3.2.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
dpage/pgadmin4:latestc332c5f6dfba
oauthlib@3.3.1
4.0.0

Open the chart page →

17
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
oauthlib@3.3.1
4.0.0

Open the chart page →

19,668
inventreeinventreeOfficialVerified publisher0.4.301 of 2See more

inventree inventree 0.4.30

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
inventree/inventree:1.5.6b61e6a7534bf
oauthlib@3.3.1
4.0.0

Open the chart page →

5,613
kubernetes-pythonjacobcolvinVerified publisher0.1.11 of 1See more

kubernetes-python jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/macropower/kubernetes-python:1.0a887b5cae4af
oauthlib@3.3.1
4.0.0

Open the chart page →

74
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
oauthlib@3.2.2
4.0.0

Open the chart page →

46,735
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
oauthlib@3.1.0
4.0.0

Open the chart page →

4,313
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
oauthlib@3.2.2
4.0.0

Open the chart page →

7,268
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
oauthlib@3.2.2
4.0.0

Open the chart page →

7,250
beetsjmmaloney40.9.61 of 1See more

beets jmmaloney4 0.9.6

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/beets:1.4.9-ls94826263aebec3
oauthlib@3.1.0
4.0.0

Open the chart page →

1,231
shynetjuniorjpdj0.1.321 of 1See more

shynet juniorjpdj 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
oauthlib@3.2.1
4.0.0

Open the chart page →

2,730
bazarrk8s-home-lab-repo11.3.21 of 1See more

bazarr k8s-home-lab-repo 11.3.2

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-operations/bazarr:1.5.680cb090162b4
oauthlib@3.2.2
4.0.0

Open the chart page →

1,900
beetsk8s-home-lab-repo3.1.11 of 1See more

beets k8s-home-lab-repo 3.1.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/home-operations/beets:2.3.1cc4975f1a0be
oauthlib@3.2.2
4.0.0

Open the chart page →

2,957
paperlessk8s-home-lab-repo11.0.11 of 1See more

paperless k8s-home-lab-repo 11.0.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
oauthlib@3.3.1
4.0.0

Open the chart page →

10,059
jupyterhub-chartk8s-jupyterhub0.1.01 of 1See more

jupyterhub-chart k8s-jupyterhub 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
truebyteinnovationllp/jupyterhub-k8s:5.5.06bf978b96279
oauthlib@3.3.1
4.0.0

Open the chart page →

1,656
authentikkagiso-me0.1.11 of 1See more

authentik kagiso-me 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/goauthentik/server:2026.2.146a71d75dfd3
oauthlib@3.3.1
4.0.0

Open the chart page →

5,011
karbkarbVerified publisher1.0.31 of 1See more

karb karb 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/xeor/karb:main647a3c938d31
oauthlib@3.3.1
4.0.0

Open the chart page →

700
karb-chartkarbVerified publisher1.0.61 of 1See more

karb-chart karb 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
ghcr.io/xeor/karb:1.0.6647a3c938d31
oauthlib@3.3.1
4.0.0

Open the chart page →

700
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
oauthlib@3.2.0
4.0.0

Open the chart page →

4,517
elastalert2kfirfer2.2.51 of 1See more

elastalert2 kfirfer 2.2.5

1 of the 1 container images this version deploys carry CVE-2026-49265.

Container imageDigestPackageFixed in
jertel/elastalert2:2.2.34dcc0ef93efc
oauthlib@3.1.1
4.0.0

Open the chart page →

1,652

Container images carrying it

471 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
knspar/phronetis-operator:0.1.60c4f0543ee58
oauthlib@3.2.2
4.0.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
oauthlib@3.2.0
4.0.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
oauthlib@3.2.0
4.0.0
1
kserve/models-web-app:v0.8.063ea05e73842
oauthlib@3.2.0
4.0.0
1
kserve/models-web-app:v0.13.073486345a602
oauthlib@3.2.2
4.0.0
1
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
oauthlib@3.2.2
4.0.0
1
kubeflownotebookswg/jupyter-web-app:v1.6.1d762690e21c1
oauthlib@3.2.1
4.0.0
1
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
oauthlib@3.2.1
4.0.0
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
oauthlib@3.2.2
4.0.0
1
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
oauthlib@3.2.1
4.0.0
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
oauthlib@3.2.2
4.0.0
1
kubitodev/traefik-ip-whitelist-sync:1.0.2aa24869319bf
oauthlib@3.2.0
4.0.0
1
langflowai/langflow:1.12.334055a07d446
oauthlib@3.3.1
4.0.0
1
langgenius/dify-api:1.0.0066035f93856
oauthlib@3.2.2
4.0.0
1
langgenius/dify-api:1.16.1dcefa5f7c47c
oauthlib@3.3.1
4.0.0
1
langgenius/dify-api:0.6.11fca918260dd6
oauthlib@3.2.2
4.0.0
1
linuxserver/bazarr:latestd24bd0048c75
oauthlib@3.3.1
4.0.0
1
linuxserver/calibre-web:0.6.24241009026e6f
oauthlib@3.3.1
4.0.0
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
oauthlib@3.1.1
4.0.0
1
linuxserver/healthchecks:4.4.2026092108a37bd6dcf2
oauthlib@3.3.1
4.0.0
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
oauthlib@3.2.2
4.0.0
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
oauthlib@3.1.1
4.0.0
1
linuxserver/medusa:v1.0.26-ls29002137158996f
oauthlib@3.3.1
4.0.0
1
linuxserver/nzbget:26.3.2026091124951ff9689d
oauthlib@3.3.1
4.0.0
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
oauthlib@3.1.0
4.0.0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
oauthlib@3.3.1
4.0.0
1
loeken/home-assistant:2026.5.14ce6abc553b3
oauthlib@3.3.1
4.0.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
oauthlib@3.2.2
4.0.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
oauthlib@3.2.2
4.0.0
1
louislam/uptime-kuma:2.4.091e963bfda56
oauthlib@3.2.2
4.0.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
oauthlib@3.2.2
4.0.0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
oauthlib@3.2.0
4.0.0
1
lsstsqre/prepuller:latest19c2dfc4e4ff
oauthlib@3.1.0
4.0.0
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
oauthlib@3.1.0
4.0.0
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
oauthlib@3.1.1
4.0.0
1
lsstsqre/wfdispatcher:lateste9feb99f524d
oauthlib@3.1.0
4.0.0
1
lumutools/kubernetes-feeder:lateste35ffa90b129
oauthlib@3.3.1
4.0.0
1
makeplane/backend-commercial:v3.3.0f587597c46b5
oauthlib@3.3.1
4.0.0
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
oauthlib@3.3.1
4.0.0
1
mathesar/mathesar:0.12.0091757cb01fe
oauthlib@3.3.1
4.0.0
1
microslac/auth:latest5c1eb1f5c64d
oauthlib@3.2.2
4.0.0
1
milesmcc/shynet:v0.13.1ba54f7797a6b
oauthlib@3.2.1
4.0.0
1
milesmcc/shynet:v0.12.0e821e31140f7
oauthlib@3.1.1
4.0.0
1
mindsdb/mindsdb:latest163011c09299
oauthlib@3.3.1
4.0.0
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
oauthlib@3.2.2
4.0.0
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
oauthlib@3.2.2
4.0.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
oauthlib@3.1.0
4.0.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
oauthlib@3.2.0
4.0.0
1
netboxcommunity/netbox:v4.6.10-5.0.291b823a05cb5
oauthlib@3.3.1
4.0.0
1
netboxcommunity/netbox:v3.7.8-2.8.09bf83b350a89
oauthlib@3.2.2
4.0.0
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.